156-215.80 · Question #205
You installed Security Management Server on a computer using GAiA in the MegaCorp home office. You use IP address 10.1.1.1. You also installed the Security Gateway on a second GAiA computer, which…
The correct answer is B. 2, 1, 3, 4, 5. This question tests the correct procedural order for establishing SIC between a Security Management Server and a Gateway that will be shipped to a remote site.
Question
Options
- A2, 3, 4, 1, 5
- B2, 1, 3, 4, 5
- C1, 3, 2, 4, 5
- D2, 3, 4, 5, 1
How the community answered
(41 responses)- A7% (3)
- B73% (30)
- C15% (6)
- D5% (2)
Why each option
This question tests the correct procedural order for establishing SIC between a Security Management Server and a Gateway that will be shipped to a remote site.
Order 2,3,4,1,5 attempts to push SIC via the Communication button (step 4) before the activation key has been configured on the gateway itself (step 1), so the key exchange would fail.
The ICA must be initialized on the SMS first (step 2) so it can issue certificates. While the gateway is still physically accessible, cpconfig is run locally to set the activation key (step 1). Once shipped, the gateway object is configured in SmartDashboard (step 3), the Communication button is used to push the SIC cert using the matching activation key (step 4), and finally the Security Policy is installed (step 5).
Order 1,3,2,4,5 attempts to initialize SIC on the gateway (step 1) before the ICA even exists on the SMS (step 2), making certificate issuance impossible.
Order 2,3,4,5,1 attempts to install the Security Policy (step 5) before the activation key is set on the gateway (step 1), meaning SIC has not been fully established and policy push would fail.
Concept tested: Check Point SIC initialization order for remote deployment
Source: https://sc1.checkpoint.com/documents/R77/CP_R77_SecurityManagement_AdminGuide/html_frameset.htm
Topics
Community Discussion
No community discussion yet for this question.